Is com.local-mcp/local-mcp safe?
Yes, with the usual care.
Safe to use. Minor gaps such as a missing repository or slower maintenance.
What to know before installing
- highShell command built from a string (injection risk)
Public scan report
scanner v0.1.2 · 2026-09-18 · same rubric, same numbers if you re-run it
1 high2 medium
- Code scan5 source files scanned3/25
- Live reliabilityremote reachable in 311ms (auth required)20/20
- Tool poisoningonly the listing description was available15/15
- Auth qualityOAuth resource metadata advertised on 40115/15
- Maintenancelast push 6 days ago15/15
- Maintainer identitynamespace and repository owner differ; GitHub account older than a year5/10
Findings (3)
- mediumnpm install lifecycle script present
install.script - highShell command built from a string (injection risk)
exec.shell-concatindex.js: …mcp-server.exe']) { const out = exec(`tasklist /FI "IMAGENAME eq ${name}" /NH /FO CSV`) if (/INFO:/… - mediumnpm install lifecycle script present
install.scriptpackage.json: …cp": "index.js" }, "scripts": { "postinstall": "node postinstall.js", "test": "nod…
Overall 73/100. Components that don't apply are left out of the denominator. Any critical finding is an F.RubricAppeal a findingJSON